---
title: "Read the whole permission document"
description: "Every group and every group's permissions in one object."
canonical: "https://gtable.app/docs/builder-api/rules/get"
updated: "2026-10-05"
---

# Read the whole permission document

`GET https://studio.gtable.app/v1/apps/{appId}/rules`

Every group and every group's permissions in one object.

Deny by default, and what a user may do is the union of their groups, so adding a group can only add. Prefer groups.get when you are working on one group. `revision` identifies this version of the document; send it back as `baseRevision` when you replace it.

Requires the `schema:read` scope. Operation `rules.get`. MCP tool `rules_get`. CLI, once published: `gtable rules get`.

## Path parameters

| Name    | Type   | Required | Description |
| ------- | ------ | -------- | ----------- |
| `appId` | string | yes      |             |
